Ardens Manager
Ardens Manager is a cloud-based analytics platform providing near real-time dashboards, benchmarking, and contract monitoring for GP practices, PCNs and ICBs. It includes population health and commissioning dashboards, improving visibility of activity, outcomes and inequalities. Embedded patient access tools provide messaging, automated recalls, appointment booking, questionnaires and online triage.
Features
- Population health dashboards: appointments, LTCs, prescribing, referrals, vaccinations, inequalities
- National contract dashboards including QOF, NCD, SMI Health Checks
- Local contract management with automated reporting workflows
- Benchmarking at Practice, PCN, INT and ICB levels
- Near real-time data extraction from EMIS, SystmOne and Medicus
- Trend and trajectory tracking for performance improvement
- Patient level insights with demographic & staff breakdowns
- Messaging via NHS App, SMS and email
- Appointment booking and questionnaires
- Automated recall, online triage and communication reporting
Benefits
- Improve performance using real time population health insight
- Strengthen national contract delivery with accurate dashboards
- Streamline local contract management and submissions
- Reduce administrative workload through automation
- Support equitable care with inequalities insight
- Enable targeted interventions with patient level data
- Increase operational efficiency and workflow consistency
- Improve access using digital booking and triage
- Reduce SMS costs via promoting NHS App first
- Support proactive planning and demand management
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 1 3 7 2 6 9 8 1 8 8 3 0 6 9
Contact
ARDENS HEALTH INFORMATICS LIMITED
Ardens Accounts Team
Telephone: 01725 762062
Email: accounts@ardens.org.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Ardens Manager is accessed through a supported browser, including Google Chrome (recommended), Firefox, Edge and Safari.
Planned maintenance is carried out outside of working hours to avoid disruption to users. - System requirements
- A supported browser - Chrome, Edge, Firefox or Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- A summary of response times can be found at https://ardens.org.uk/policies/product-specification#kpi. We aim to respond to all support requests within 3 working days of receipt although we strive to respond much quicker. Serious incidents will be acknowledged within 4 hours of occurrence and resolved within 2 working days (excluding issues outside of Ardens control). Urgent Change Requests including updates & issues will be completed within 5 working days and non-urgent change requests within 20 working days. The Ardens Support Desk is operational Monday to Friday. It is closed at the weekend.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Ardens utilises FreshChat supplied by Freshworks for WebChat functionality. The FreshChat application has been tested by a qualified accessibility tester and Certified Professional in Web Accessibility (CPWA) by the International Association of Accessibility Professionals (IAAP)). Freshworks also regularly validate and test their website for compliance with WCAG.
- Onsite support
- Yes
- Support levels
-
All of our customers have access to the same support levels. Our expert post-implementation Support Team is available from 08:30-17:00 Monday – Friday and they are responsible for answering customer queries and ensuring that Ardens Manager has been fully installed and optimised successfully on our customer’s systems. Further support can be provided depending on customer need, such as customising Ardens Manager dashboards to meet specific, local contract reporting requirements.
All customers have access to:
Screensharing facilities with Ardens’ staff to rectify problems
Webinars
Users guides
Online forums and Facebook group chats discussing Ardens
Email support
Telephone Support
Webchat
Our post-implementation Support Team
Online learning platform - Ardens Academy - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
As part of the Ardens initial setup package, we provide free training to support deployment and adoption. These will be tailored to the customer’s specific systems, most used templates and customer type (e.g. individual GP practice or GP Federation or ICB) to ensure the customer’s full understanding, confidence and ease of use. Training can also be delivered for more specific topics such as Medicines Management. Additionally, all users are provided with an online set-up guide and email instructions. Documentation will be tailored to customer type and customer location to meet each customer’s specific needs.
Users can visit the support page on our website to access resources for further assistance such as:
• Frequently asked questions
• A contact form and our Support Desk for specific queries
• News and updates
• Webinars
• Guides
• Training videos
• Help via screensharing
• Online forums and Facebook group chats - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Ardens will retain and process data only for the duration of the Supply Contract. Following the expiry of a contract between Ardens and the data controller, all patient-level data is deleted. This deletion is completed either upon request, or, automatically within 28 days (whichever is sooner). This time frame accounts for the process including removing data extractions from the primary clinical system and the physical deletion process. The GP Practice can choose either to have its organisational data returned via a secure export or to request its permanent deletion.
- End-of-contract process
- At the end of a contract the customer is able to choose from a number of options, this ranges from continuing with a different Ardens Package or ending the contract with subsequent data extraction and deletion from the platform. No charge is made for this.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding training documentation is designed to be clear, comprehensive and easily accessible to customers.
When new customers are onboarded, they are provided with information on the training resources to get them started. This is included within the onboarding email to clients. This includes:
Contact email (training@ardens.org.uk) to book practice, PCN or ICB level training.
Access to Ardens Academy to enrol on the ‘Getting Started with Ardens Manager’ course to help the customers navigate the system efficiently.
Links to support articles covering instructions on how to use the resources, common frequently asked questions and best practices to ensure customers are making the most of the platform.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Ardens Manager allows a variety of customisation options. All users can apply custom filters ranging from time frames to co-existing long-term conditions and other demographic factors.
Additionally, a Local Content package is available where content is customised to the local requirements of the commissioner.
Scaling
- Independence of resources
- Ardens Manager can support a large number of concurrent users. We have heavily over-provisioned environments, and auto scaling groups in place to deal with additional users as needed. We monitor the user base closely and have the ability to add capacity very quickly if required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We can provide a range of service metrics for users on request. This includes reporting on uptime and platform usage. Usage data includes the number of active users, the number of actions taken by users and the most popular pages and functionalities.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Data held within Amazon Web Services is also subject to the Suppliers technical and organisational controls for the protection of data at rest.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export data relevant to their role-based permissions and NHS CIS authentication level. This includes securely exporting patient lists for direct patient care or CSVs/PDF summaries of aggregated non-patient identifiable data for commissioning and Population Health Management.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- PNG (in development pipeline)
- JPEG (in development pipeline)
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Ardens Manager has uptime of over 99.98% over the last 12 months. In the unlikely event of a significant outage of management functions, we will compensate our clients with service credits.
- Approach to resilience
-
Our services are hosted with a global leader in cloud infrastructure and architected with high availability and redundancy in mind. The service includes multiple layers of security and environmental separation.
Ardens resilience protocol and safeguards are available on request - Outage reporting
- We report any outages to our clients as quickly as possible, and within 60 minutes as a maximum. We alert via webpage notifications, emails and our Ardens Chat Facebook group.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to the platform and it’s hosting management environment itself is limited by roles and Access Control Lists, and controlled by Single Sign On and multifactor authentication.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Ardens meets the requirements of the NHS Data Security and Protection Toolkit and are fully accredited with ISO27001 and Cyber Essentials Plus. A range of policies and procedures support the security of our system. These are available to clients on request and though our website.
All staff are trained on security as part of their induction, and receive regular training updates to ensure continued compliance. For those with access to sensitive parts of software – for example, our development environment – additional security training is carried out, as well as appropriate pre-employment checks. These include DBS.
Our reporting structure is in line with our security policy. Our SIRO is a member of the Board, and has responsibility for identifying and mitigating risks. Overall, our Chief Executive has overall responsibility for security, supported by individual product leads. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Our change management process is handled through ClickUp. When changes to a component are requested a ticket is generated containing information regarding impact, testing procedures, acceptance criteria, roll back procedures and any post deployment verifications required.
Work is conducted and stored within an enterprise class version control system, with tests included as part of any new feature. Code is written according to our secure coding guidelines, and peer reviewed by at least two senior team members before being merged in to the main branch for deployment to a QA environment, where it is retested before going to production. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our platform is hosted within AWS, who provide multiple levels of support to secure their infrastructure. We monitor our environment in AWS using Guard Duty and Security Hub, and all updates are patched in regularly.
Our physical network is protected by a 3rd party Security Operations Centre, monitored 24x7, as well as our in-house team. We also use Microsoft 365 Security Centre, which informs us in real time of vulnerabilities discovered in the wild, as well as providing threat intelligence. Critical and high-severity vulnerabilities are remediated within 14 days. Externally facing critical and high vulnerabilities are prioritised within 7 days. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our platform is hosted within AWS, protected by a Web Application Firewall. We monitor activity within our environment in AWS Guard Duty, which proactively informs us of unusual activity.
For our platform, we have the ability to Hotfix in changes to plug gaps very quickly using our deployment processes. We also undergo regular penetration testing and all code is written according to secure coding guidelines.
For physical networks within our offices, we have 24x7 monitoring from a 3rd party Security Operations Centre on top of our in house team. A compromised machine can be remotely removed from the network immediately. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Ardens maintains a comprehensive incident management framework aligned with ISO 27001 and compliant with the NHS Data Security and Protection Toolkit. Incidents can be reported through dedicated internal channels or via our Service Desk, and all staff follow our documented Incident Management Plan. Severity-based response times ensure prompt action: Minor incidents (minor issues for a small number of recipients) are acknowledged within 4 hours and resolved within 2 working days, whilst critical incidents will be reported to the NHS Service Bridge. Incident reports are provided to clients in accordance with our Terms of Supply and Use or upon request.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Ardens Manager offers a free one-month trial providing full access to all standard National Content Dashboards. Training is included where needed. Localisation may be considered for large-scale trials. The trial is quick to set up, has no commitment and allows practices to assess suitability in a live environment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 2.5%
- Between £1,000,001 and £2,500,000
- 2.5%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 2.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 30 January 2025
- What the ISO/IEC 27001 doesn’t cover
- All annex A controls are covered within the Statement of Applicability
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 97e52154-3c3f-4b3c-ba66-ae51741dc21d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Fd7e775f-36d0-4672-97bd-2291d7f3e021
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
-